216.73.216.220

CVE-2026-31848

· Published 23/03/2026 13:16 · Modified 23/03/2026 14:31

Labels: CVE-2026-31848 2026-03-23309f9ea4-e3e9-4c6c-b79d-e8eb01244f2cCVE-2026-31848CWE-312

Essential information

Published
23/03/2026 13:16
Modified
23/03/2026 14:31
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores administrative authentication material in the ecos_pw cookie using a reversible Base64-encoded format with a static suffix. An attacker who obtains or derives this cookie value can forge a valid administrative session and gain unauthorized access to the device.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
NVD
View on NVD

Affected products (CPE)

ProductCPE
nexxt solutions / nebula 300+ cpe:2.3:a:nexxt_solutions:nebula_300+:*:*:*:*:*:*:*

References